Re: [PATCH net] sctp: reject stale cookies with mismatched verification tags

Xin Long <[email protected]> Fri, 24 Jul 2026 11:50:39 -0400
Newsgroups org.kernel.vger.linux-sctp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev,org.kernel.vger.stable
Message-ID <CADvbK_d9Q=+dZKy306Bv+PV2AjYbdo0WvX9w7t2=zVMbc=UFJA@mail.gmail.com>
On Thu, Jul 23, 2026 at 6:56=E2=80=AFPM Yuxiang Yang
<[email protected]> wrote:
>
> sctp_unpack_cookie() skips cookie expiration checks whenever an
> association already exists.  This is broader than the exception in
> RFC 9260 Section 5.2.4.
>
> For an existing association, Section 5.2.4 permits an expired State
> Cookie only when both Verification Tags in the cookie match the current
> association.  Otherwise, the packet SHOULD be discarded and a Stale
> Cookie ERROR MUST be sent.
>
> The broad check lets an expired Action A restart cookie reach
> sctp_sf_do_dupcook_a().  In a runtime test with the default 60 second
> cookie lifetime, replaying such a cookie after 65 seconds returned a
> COOKIE-ACK and restarted the association.
>
> Check cookie expiration unless both Verification Tags match.  This
> preserves the Action D exception for a lost COOKIE ACK while rejecting
> expired cookies in all other cases.
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Cc: [email protected]
> Signed-off-by: Yuxiang Yang <[email protected]>
> ---
>  net/sctp/sm_make_chunk.c | 11 +++++++----
>  1 file changed, 7 insertions(+), 4 deletions(-)
>
> diff --git a/net/sctp/sm_make_chunk.c b/net/sctp/sm_make_chunk.c
> index c02809264..a1c0334a1 100644
> --- a/net/sctp/sm_make_chunk.c
> +++ b/net/sctp/sm_make_chunk.c
> @@ -1802,9 +1802,9 @@ struct sctp_association *sctp_unpack_cookie(
>                 goto fail;
>         }
>
> -       /* Check to see if the cookie is stale.  If there is already
> -        * an association, there is no need to check cookie's expiration
> -        * for init collision case of lost COOKIE ACK.
> +       /* Check to see if the cookie is stale.  RFC 9260 Section 5.2.4
> +        * exempts an expired cookie only when both Verification Tags mat=
ch
> +        * the current association.
>          * If skb has been timestamped, then use the stamp, otherwise
>          * use current time.  This introduces a small possibility that
>          * a cookie may be considered expired, but this would only slow
> @@ -1815,7 +1815,10 @@ struct sctp_association *sctp_unpack_cookie(
>         else
>                 kt =3D ktime_get_real();
>
> -       if (!asoc && ktime_before(bear_cookie->expiration, kt)) {
> +       if ((!asoc ||
> +            asoc->c.my_vtag !=3D bear_cookie->my_vtag ||
> +            asoc->c.peer_vtag !=3D bear_cookie->peer_vtag) &&
> +           ktime_before(bear_cookie->expiration, kt)) {
>                 suseconds_t usecs =3D ktime_to_us(ktime_sub(kt, bear_cook=
ie->expiration));
>                 __be32 n =3D htonl(usecs);
>
> --
> 2.34.1
>
Acked-by: Xin Long <[email protected]>